Impact
A heap‑based buffer overflow exists in the Windows Imaging Component that permits an attacker who can send specially crafted data over a network to execute arbitrary code on the host. This remote code execution flaw can be exploited without authentication and could allow the attacker to gain full control of the affected system, compromising confidentiality, integrity, and availability.
Affected Systems
The vulnerability affects Microsoft Windows 10 releases 1607, 1809, 21H2 and 22H2, Windows 11 releases 23H2, 24H2, 25H2, 26H1, and Windows Server editions from 2012 through 2025. The flaw is present in both 32‑bit and 64‑bit builds and in ARM64 Windows 11 configurations.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not listed, suggesting no quantified probability but the lack of a KEV listing implies no known mass‑scale exploitation yet. However the flaw is exploitable over the network, meaning an attacker can remotely trigger the overflow by sending crafted image data to the vulnerable component on the target host. Because no authentication is required, the risk is significant for public or exposed services that handle image data.
OpenCVE Enrichment